Q Gotten Wrong Flashcards

1
Q

How are NACL rules evaluated?

A

From the lowest numbered rule to the highest. Once a match is found, it is applied immediately regardless of what higher numbered rules say

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When can you change the security group of an instance?

A

When it is in the running or stopped state

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is S3 notifications?

A

A feature that enables you to receive notifications when certain events happen in your bucket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where should you store certification certificates?

A

AWS Artifact

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where should you store SSL Certificates?

A

AWS Certificate Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What service can provide temporary security credentials?

A

AWS Security Token Service (STS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Amazon MSK?

A

A service meant for applications that currently use or are going to use Apache Kafka for messaging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the most efficient way to automate EC2 instance monitoring and maintenance when the instances report health check failures?

A

Create an Amazon Cloudwatch alarm that monitors an Amazon EC2 instance and automatically reboots the instance if a health check fails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a cron job?

A

It allows users to schedule a task or command to run automatically at a specified time and interval, without the need for user interaction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Amazon’s immutable and cryptographically verifiable database solution?

A

Amazon Quantum Ledger Database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Amazon Neptune?

A

a fully managed graph database service offered by Amazon Web Services (AWS). It is designed to store and query highly connected data, such as social networking, recommendation engines, and knowledge graphs, using graph theory.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Amazon AppFlow?

A

a fully managed service for easily automating the exchange of data between SaaS vendors and AWS services like Amazon S3. You can transfer up to 100 gibibytes per flow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Amazon EKS?

A

Elastic Kubernetes Service is a fully managed service offered by Amazon Web Services (AWS) for deploying, scaling, and managing Kubernetes clusters. Kubernetes is an open-source container orchestration platform used for automating the deployment, scaling, and management of containerized applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can you append to a URL to review scripts used to bootstrap instances at runtime?

A

user-data/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If you need synchronous data replication for a RDS database, what should you do?

A

RDS Multi-AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Should OLAP workloads or OLTP workloads go in DynamoDB?

A

OLTP; OLAP workloads usually need a relational database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is AWS Step Functions?

A

Using AWS Step Functions, developers can create workflows that coordinate the execution of AWS Lambda functions, EC2 instances, Fargate containers, and other AWS services, as well as custom applications and services running on-premises or in other clouds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is AWS Step Functions?

A

Using AWS Step Functions, developers can create workflows that coordinate the execution of AWS Lambda functions, EC2 instances, Fargate containers, and other AWS services, as well as custom applications and services running on-premises or in other clouds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

If you want a low stress way to deploy and manage applications in the AWS Cloud, what should you use?

A

Elastic Beanstalk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

If you want a low stress way to deploy and manage applications in the AWS Cloud, what should you use?

A

Elastic Beanstalk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

When an auto-scaling group begins to scale in, what instance does it terminate first?

A

The instance launched from the oldest launch configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What type of load balancer best handles very very high traffic and can maintain high throughput at low latency?

A

Network Load Balancer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Can AWS Cost and Usage Reports automatically store updated reports in S3?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

If you need to stop instances that have been idle for long periods of time, what service should you use?

A

CloudWatch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Can you delete the default security group? Can you change the group’s rules?

A

No, Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What service can help ensure all your firewall rules across multiple accounts and regions are consistent?

A

AWS Firewall Manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Is each subnet associated with one security group?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

Must each subnet reside entirely within one AZ?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

How many subnets that you create get associated with the main route table for the VPC?

A

Every

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is the best way you speed up the transfer of data to an S3 bucket?

A

Use Transfer Acceleration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

How many security groups can be attached to an EC2 instance?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is Amazon Macie?

A

a fully managed data security and data privacy service that utilizes machine learning and pattern matching

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What service can help store data in a secure manner and analyze said data and send alerts depending on whether the data is improperly stored?

A

Amazon Macie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

if you want to identify the root cause of potential security issues, what should you use?

A

Amazon Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Can you modify or delete the * All Traffic Deny rule in NACL’S?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is the best way to grant permissions to AWS services?

A

Create an IAM Role that you attach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Can you change the rules on the default network ACL?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

if you need multiple versions of a launch template or configuration, which service should you use?

A

launch templates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

if you need multiple versions of a launch template or configuration, which service should you use?

A

launch templates

40
Q

Do private IP addresses need to be globally unique?

A

No

41
Q

What step can you take with your database to configure high-availability and ensure minimal downtime?

A

Enable Multi-AZ failover

42
Q

Your EC2 workloads need low-latency network performance, high network throughput, and a tightly-coupled node-to-node communication. What’s the best measure you can do to ensure this throughput?

A

Launch your instances in a cluster placement group

43
Q

It’s important that each request is processed only 1 time, should you use SQS FIFO or SQS Standard?

A

SQS FIFO

44
Q

What is the SQS FIFO batch limit?

A

3000

45
Q

What is the SQS FIFO batch limit?

A

3000

46
Q

If high-speed querying is very important, what database should you use?

A

DynamoDB

47
Q

How long is the default Auto Scaling Group cooldown?

A

5 minutes

48
Q

What is AWS Athena?

A

a serverless query service provided by Amazon Web Services (AWS). It allows you to analyze and query data that is stored in Amazon S3 using SQL (Structured Query Language), without the need to manage any infrastructure or servers.

49
Q

Can AWS Redshift hold session state data?

A

No

50
Q

Should you assign roles or hard code credentials in to give access to resources?

A

assign roles

51
Q

Which AWS service allows you to kick off the collection of metrics and generate recommendations for incorrectly sized EC2 instances?

A

AWS Compute Optimizer

52
Q

How can you communicate with DynamoDB or S3 without traversing the internet or leaving the Amazon Network?

A

Use VPC endpoints

53
Q

You need to ensure that your RDS database can only be accessed using the profile credentials specific to your EC2 instances (via an authentication token). How can you achieve this?

A

Using IAM database authentication

54
Q

You need to ensure that your RDS database can only be accessed using the profile credentials specific to your EC2 instances (via an authentication token). How can you achieve this?

A

Using IAM database authentication

55
Q

You have been asked to implement a Cloud Security Posture Management (CSPM) service that performs security best practice checks, aggregates alerts, and enables automated remediation. Which AWS service would meet this requirement?

A

AWS Security Hub

56
Q

What is AWS’s Cloud Security Posture Management service?

A

AWS Security Hub

57
Q

What is port 22 for?

A

Port 22 is typically used for the Secure Shell (SSH) protocol, which is a network protocol used for secure remote access to a computer system.

58
Q

What is port 88 for?

A

Port 88 is a network authentication protocol that provides secure communication between clients and servers.

59
Q

What is 443 for?

A

Port 443 is typically used for HTTPS (Hypertext Transfer Protocol Secure)

60
Q

How can you provide temporary access to the public for your S3 buckets?

A

Presigned URL’s with expiration dates

61
Q

You want to have a centralized method of storing AWS CloudTrail logs for all accounts and alert on any notifications regarding compliance violations with AWS services in the member accounts. What solution would be the best fit for this scenario?

A

AWS Control Tower that utilizes SNS Notifications

62
Q

What is AWS Service Catalog?

A

IT administrators can select which AWS services, third-party applications, and IT services they want to make available to their users, define the configuration options for each service, and then publish the catalog to their users.

63
Q

What is AWS Control Tower?

A

allows you to implement account governance and compliance enforcement for an AWS organization.

64
Q

If you need to attach a volume to multiple instances, what should you use?

A

Amazon EBS Multi-Attach

65
Q

Can Lambda be used to automatically handle bursts in traffic?

A

Yes as Lambda can be invoked many times simultaneously

66
Q

What is CloudFront Origin Access Indentity?

A

This is used for authentication internally between S3 and CloudFront

67
Q

You need to provide access to hundreds of private files served by your CloudFront distribution. What should you use?

A

CloudFront signed cookies

68
Q

If you need a fixed IP address, what should you create?

A

An elastic IP Address

69
Q

If you need to store and retireve objects in Amazon S3 using industry standard-file protocols such as Network File System and Server Message Block, what service should you use?

A

AWS File Gateway

70
Q

Does SQS scale automatically?

A

Yes

71
Q

What AWS service would you recommend to use for MongoDB?

A

Amazon DocumentDB

72
Q

What EBS Volume type gives you the highest performance in terms of IOPS?

A

EBS Provisioned IOPS SSD (io2 Block Express)

73
Q

What EBS Volume type gives you the highest performance in terms of IOPS?

A

EBS Provisioned IOPS SSD (io2 Block Express)

74
Q

If you need a database that allows constant updates to schemas without any downtime or performance issues, what database should you use?

A

DynamoDB

75
Q

What is a Cassandra compatible AWS database?

A

Amazon Keyspaces

76
Q

Is Aurora Serverless a cost effective solution?

A

Yes

77
Q

Is Lambda a cost effective solution?

A

Yes

78
Q

Can Macie scan images for vulnerabilties?

A

No

79
Q

Must an S3 bucket name always be the same as the domain name if you are hosting a static website?

A

Yes

80
Q

You need a service that support RabbitMQ or Apache ActiveMQ, what should you use?

A

Amazon MQ

81
Q

What does AWS Batch Manager do?

A

Nothing, it isnt a service (AWS Batch is but not Batch Manager)

82
Q

What can Amazon X-Ray do?

A

identify and diagnose issues with your applications, such as latency, errors, or other performance bottlenecks.

83
Q

What can Amazon X-Ray do?

A

identify and diagnose issues with your applications, such as latency, errors, or other performance bottlenecks.

84
Q

Can Lambda help provision architecture?

A

No

84
Q

Can Lambda help provision architecture?

A

No

85
Q

What is Amazon Pinpoint?

A

allows users to easily engage millions of customers via different communication channels. The service also offers the ability to leverage machine learning models to better understand customer interactions for future engagements

86
Q

What is DynamoDB streams?

A

a feature of Amazon Web Services (AWS) DynamoDB that provides a time-ordered sequence of item-level changes made to a DynamoDB table.

87
Q

If you need a gateway able to interface with iSCSI, what should you use?

A

Volume Gateway

88
Q

Can you assign a static IP address to an application load balancer?

A

No

89
Q

Can you assign a static IP address to a network load balancer?

A

Yes

90
Q

What happens when the primary database in Aurora fails?

A

Aurora automatically fails over by either promoting an existing Aurora Replica to the new primary instance or creating a new primary instance.

91
Q

What is the best way to automatically back up EBS volumes?

A

Use Amazon Data Lifecycle Manager to automate the creation of EBS snapshots.

92
Q

From least expensive to most expensive, list the AWS Support Service Teirs

A

Developer, Business, Enterprise

93
Q

What is the most cost effective EBS volume for sequential I/O operations?

A

Cold HDD

94
Q

If you want to use Apache Kafka with AWS, what service should you utilize?

A

Amazon MSK

95
Q

What is Amazon Lex?

A

allows you to build conversational interfaces in your applications using natural-language models.